Home | History | Annotate | Line # | Download | only in krb5
      1  1.1     elric /*	$NetBSD: rd_rep.c,v 1.2 2017/01/28 21:31:49 christos Exp $	*/
      2  1.1     elric 
      3  1.1     elric /*
      4  1.1     elric  * Copyright (c) 1997 - 2001 Kungliga Tekniska Hgskolan
      5  1.1     elric  * (Royal Institute of Technology, Stockholm, Sweden).
      6  1.1     elric  * All rights reserved.
      7  1.1     elric  *
      8  1.1     elric  * Redistribution and use in source and binary forms, with or without
      9  1.1     elric  * modification, are permitted provided that the following conditions
     10  1.1     elric  * are met:
     11  1.1     elric  *
     12  1.1     elric  * 1. Redistributions of source code must retain the above copyright
     13  1.1     elric  *    notice, this list of conditions and the following disclaimer.
     14  1.1     elric  *
     15  1.1     elric  * 2. Redistributions in binary form must reproduce the above copyright
     16  1.1     elric  *    notice, this list of conditions and the following disclaimer in the
     17  1.1     elric  *    documentation and/or other materials provided with the distribution.
     18  1.1     elric  *
     19  1.1     elric  * 3. Neither the name of the Institute nor the names of its contributors
     20  1.1     elric  *    may be used to endorse or promote products derived from this software
     21  1.1     elric  *    without specific prior written permission.
     22  1.1     elric  *
     23  1.1     elric  * THIS SOFTWARE IS PROVIDED BY THE INSTITUTE AND CONTRIBUTORS ``AS IS'' AND
     24  1.1     elric  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     25  1.1     elric  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     26  1.1     elric  * ARE DISCLAIMED.  IN NO EVENT SHALL THE INSTITUTE OR CONTRIBUTORS BE LIABLE
     27  1.1     elric  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     28  1.1     elric  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     29  1.1     elric  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     30  1.1     elric  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     31  1.1     elric  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     32  1.1     elric  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     33  1.1     elric  * SUCH DAMAGE.
     34  1.1     elric  */
     35  1.1     elric 
     36  1.1     elric #include "krb5_locl.h"
     37  1.1     elric 
     38  1.1     elric KRB5_LIB_FUNCTION krb5_error_code KRB5_LIB_CALL
     39  1.1     elric krb5_rd_rep(krb5_context context,
     40  1.1     elric 	    krb5_auth_context auth_context,
     41  1.1     elric 	    const krb5_data *inbuf,
     42  1.1     elric 	    krb5_ap_rep_enc_part **repl)
     43  1.1     elric {
     44  1.1     elric     krb5_error_code ret;
     45  1.1     elric     AP_REP ap_rep;
     46  1.1     elric     size_t len;
     47  1.1     elric     krb5_data data;
     48  1.1     elric     krb5_crypto crypto;
     49  1.1     elric 
     50  1.2  christos     *repl = NULL;
     51  1.1     elric     krb5_data_zero (&data);
     52  1.1     elric 
     53  1.1     elric     ret = decode_AP_REP(inbuf->data, inbuf->length, &ap_rep, &len);
     54  1.1     elric     if (ret)
     55  1.1     elric 	return ret;
     56  1.1     elric     if (ap_rep.pvno != 5) {
     57  1.1     elric 	ret = KRB5KRB_AP_ERR_BADVERSION;
     58  1.1     elric 	krb5_clear_error_message (context);
     59  1.1     elric 	goto out;
     60  1.1     elric     }
     61  1.1     elric     if (ap_rep.msg_type != krb_ap_rep) {
     62  1.1     elric 	ret = KRB5KRB_AP_ERR_MSG_TYPE;
     63  1.1     elric 	krb5_clear_error_message (context);
     64  1.1     elric 	goto out;
     65  1.1     elric     }
     66  1.1     elric 
     67  1.1     elric     ret = krb5_crypto_init(context, auth_context->keyblock, 0, &crypto);
     68  1.1     elric     if (ret)
     69  1.1     elric 	goto out;
     70  1.2  christos     ret = krb5_decrypt_EncryptedData(context,
     71  1.2  christos 				     crypto,
     72  1.2  christos 				     KRB5_KU_AP_REQ_ENC_PART,
     73  1.2  christos 				     &ap_rep.enc_part,
     74  1.2  christos 				     &data);
     75  1.1     elric     krb5_crypto_destroy(context, crypto);
     76  1.1     elric     if (ret)
     77  1.1     elric 	goto out;
     78  1.1     elric 
     79  1.1     elric     *repl = malloc(sizeof(**repl));
     80  1.1     elric     if (*repl == NULL) {
     81  1.2  christos 	ret = krb5_enomem(context);
     82  1.1     elric 	goto out;
     83  1.1     elric     }
     84  1.1     elric     ret = decode_EncAPRepPart(data.data, data.length, *repl, &len);
     85  1.1     elric     if (ret) {
     86  1.1     elric 	krb5_set_error_message(context, ret, N_("Failed to decode EncAPRepPart", ""));
     87  1.2  christos         goto out;
     88  1.1     elric     }
     89  1.1     elric 
     90  1.1     elric     if (auth_context->flags & KRB5_AUTH_CONTEXT_DO_TIME) {
     91  1.1     elric 	if ((*repl)->ctime != auth_context->authenticator->ctime ||
     92  1.1     elric 	    (*repl)->cusec != auth_context->authenticator->cusec)
     93  1.1     elric 	{
     94  1.1     elric 	    ret = KRB5KRB_AP_ERR_MUT_FAIL;
     95  1.2  christos 	    krb5_clear_error_message(context);
     96  1.1     elric 	    goto out;
     97  1.1     elric 	}
     98  1.1     elric     }
     99  1.1     elric     if ((*repl)->seq_number)
    100  1.1     elric 	krb5_auth_con_setremoteseqnumber(context, auth_context,
    101  1.1     elric 					 *((*repl)->seq_number));
    102  1.1     elric     if ((*repl)->subkey)
    103  1.1     elric 	krb5_auth_con_setremotesubkey(context, auth_context, (*repl)->subkey);
    104  1.1     elric 
    105  1.1     elric  out:
    106  1.2  christos     if (ret) {
    107  1.2  christos         krb5_free_ap_rep_enc_part(context, *repl);
    108  1.2  christos         *repl = NULL;
    109  1.2  christos     }
    110  1.2  christos     krb5_data_free(&data);
    111  1.2  christos     free_AP_REP(&ap_rep);
    112  1.1     elric     return ret;
    113  1.1     elric }
    114  1.1     elric 
    115  1.1     elric KRB5_LIB_FUNCTION void KRB5_LIB_CALL
    116  1.1     elric krb5_free_ap_rep_enc_part (krb5_context context,
    117  1.1     elric 			   krb5_ap_rep_enc_part *val)
    118  1.1     elric {
    119  1.1     elric     if (val) {
    120  1.1     elric 	free_EncAPRepPart (val);
    121  1.1     elric 	free (val);
    122  1.1     elric     }
    123  1.1     elric }
    124